Thursday, August 11, 2022
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Hacking

Hackers Exploiting a Critical Vulnerability in Zyxel Firewall & VPN Devices

Researcher by Researcher
May 17, 2022
in Hacking
0
Hackers Exploiting a Critical Vulnerability in Zyxel Firewall & VPN Devices
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Critical Vulnerability Zyxel Firewall

Several hackers have newly begun exploiting a recently patched critical vulnerability, identified as CVE-2022-30525, which is affecting business firewall and VPN devices from Zyxel.

In response to this vulnerability, the cybersecurity experts at Rapid7 have discovered that a number of Zyxel firewalls supporting ZTP like the ATP series, the VPN series, and the USG FLEX series, are vulnerable to this security flaw.

The exploit can enable an attacker to trigger an arbitrary command injection remotely without having to authenticate, enabling the setting up of a reverse shell in most cases.

Affected Models & Firmware Versions

Here below we have mentioned all the affected models along with their respective firmware versions:-

  • USG FLEX 100, 100W, 200, 500, 700 (Firmware: ZLD5.00 thru ZLD5.21 Patch 1)
  • USG20-VPN, USG20W-VPN (Firmware: ZLD5.10 thru ZLD5.21 Patch 1)
  • ATP 100, 200, 500, 700, 800 (Firmware: ZLD5.10 thru ZLD5.21 Patch 1)

Both small branch deployments and corporate headquarters deployments of the affected firewall are advertised. 

VPN solutions, as well as SSL inspection, web filtering, intrusion protection, and email security, are provided by the company, which advertises a throughput of up to 5GB per second through its firewalls.

It has been noted that the European Union is the region with the most potential vulnerabilities, with France and Italy having the largest numbers.

Over 15,000 of these affected models are visible on the Shodan site, which indicates that they are relatively popular.

The flaw – CVE-2022-30525

It is possible to remotely inject commands into the affected models via the administrative HTTP interface without authenticating via the HTTP API. Here, the “nobody” user is used to execute all commands on the server. 

Lib_wan_settings.py contains the vulnerability that an attacker can exploit by bypassing unsanitized attacker input into the os.system method, due to the fact that /ztp/cgi-bin/handler URI has been used to exploit this vulnerability.

This vulnerability is triggered by the setWanPortSt command which is invoked in conjunction with the vulnerable functionality.

Metasploit Module

It has been found that this vulnerability has been exploited by a Metasploit module. A nobody Meterpreter session can be established by using the Metasploit module.

On top of that, Metasploit engages in the injection of commands into the mtu field.

Recommendation

Zyxel’s uncoordinated disclosure was discovered by Rapid7 independently on May 9, 2015. And this issue was addressed by Zyxel on April 28, 2022, in a patch release.

It is highly recommended that you install the vendor patch as soon as possible. If you have an automatic firmware update option, make sure that it is enabled. Inspect the web interface that you use to manage the system and disable WAN access.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity and hacking news updates.





Source link

Related articles

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

August 10, 2022
Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

August 8, 2022
Tags: criticaldevicesExploitingFirewallHackersVPNvulnerabilityZyxel
Share76Tweet47

Related Posts

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

Hackers Use Open Redirect Vulnerabilities to Deliver Phishing Content

August 10, 2022
0

Researchers at Resecurity noticed threat actors leveraging Open Redirect Vulnerabilities which is popular in online services and apps to evade...

Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

Hackers Exploiting High-Severity Zimbra Flaw to Steal Email Account Credentials

August 8, 2022
0

Zimbra CVE-2022-27824 has been added to the CISA’s “Known Exploited Vulnerabilities” catalog as a new vulnerability. Hackers are actively exploiting...

24-Year-Old Australian Hacker Arrested For Creating and Selling Spyware

24-Year-Old Australian Hacker Arrested For Creating and Selling Spyware

August 2, 2022
0

A 24-year-old man was arrested and charged with creating and selling spyware, triggering a global law enforcement operation. As a...

Critical SonicWall Flaw Allows SQL injection

Critical SonicWall Flaw Allows SQL injection

July 25, 2022
0

A critical SQL injection (SQLi) vulnerability was recently patched by the network security company SonicWall as a result of a...

Entrust Hacked – Attackers Stole Data From Internal Systems

Entrust Hacked – Attackers Stole Data From Internal Systems

July 25, 2022
0

Entrust, a big name in digital security, announced recently on its website that it has been attacked by hackers. During...

Load More
  • Trending
  • Comments
  • Latest
Brave browser’s Tor mode exposed users’ dark web activity

Brave browser’s Tor mode exposed users’ dark web activity

February 18, 2022
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
A first look at threat intelligence and threat hunting tools

A first look at threat intelligence and threat hunting tools

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
U.S. Gov Offers $5M Reward For North Korean Cybercrime Intel

How Three Ransomware Groups Targeted One Vulnerable Network

August 11, 2022
High-Severity Flaw in Argo CD is Information Leak Risk

Organizations Warned of Critical Vulnerabilities in NetModule Routers

August 11, 2022
Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

August 11, 2022
Makulu Linux Shift makes shifting between desktop layouts easy

Makulu Linux Shift makes shifting between desktop layouts easy

August 10, 2022

Recent Posts

U.S. Gov Offers $5M Reward For North Korean Cybercrime Intel

How Three Ransomware Groups Targeted One Vulnerable Network

August 11, 2022
High-Severity Flaw in Argo CD is Information Leak Risk

Organizations Warned of Critical Vulnerabilities in NetModule Routers

August 11, 2022
Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

Join the SD-WAN webinar: How to Extend Network Visibility and Optimize the SaaS Experience

August 11, 2022

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • Malware
  • Networking
  • Protection

Tags

Access Android attack Attacks banking BiWeekly bug Cisco critical Cyber Cybersecurity Data devices Digital exploited financial Finds Fintech Flaw flaws Google Group Hackers Krebs Latest malware Microsoft million Network News open Payments phishing Ransomware RoundUp security Software TFT Threat Top vulnerability warns Week Windows zeroday

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved